We have discovered an advanced persistent threat (APT) group that primarily targets online gambling sites. This group, which we have dubbed Earth Berberoka (aka GamblingPuppet), uses old yet upgraded malware families that have been attributed to Chinese-speaking actors, including PlugX and Gh0st RAT. It also uses a brand-new multistage malware family, which we have dubbed PuppetLoader. The malware families used by Earth Berberoka are multiplatform, targeting the Windows, Linux, and macOS operating systems.
Targets
Based on our analysis, we believe that Earth Berberoka’s primary targets have been gambling websites in China. However, we also have evidence that the group has targeted nongambling sites, including one education-related government institution, two IT services companies, and one electronics manufacturing company.
From Dec. 12, 2020, to April 29, 2022, we logged 15 downloads of a fake Adobe Flash Player installer in China, eight redirects from certain websites to the malicious Adobe Flash Player website (five from a legitimate news website in the US and three from an unknown website, two of which were from Hong Kong and one from Malaysia), and one PlugX DLL detection in Taiwan.

Earth Berberoka’s keyloggers generated logs that indicated that a Malaysia-based hosting provider was being compromised. A similar log file found in the wild contained an IP address belonging to a Chinese gambling website. A third log file contained the login page URL of another Chinese gambling website. These last two files strengthened our belief that the gambling industry had indeed been a major target of Earth Berberoka.
Hints of Earth Berberoka’s targeted countries can be found in one of the backdoored applications that the group has used. The first hint is that the registration process is restricted to the US, Canada, and countries in Asia, including China, Hong Kong, Macao, Taiwan, the Philippines, Japan, and South Korea. Another hint resides in the decrypted configuration files from samples of Xnote and HelloBot, two malware families that the group has used to target the Linux platform. Based on our analysis, these configuration files contain some words that might relate to gambling companies.
Infection vectors
Earth Berberoka has used different infection vectors in the delivery of some of the malware families that it has employed in its campaign. These include a supposedly secure chat app named MiMi, a fake cryptocurrency exchange app, and a website for a malicious Adobe Flash Player installer.
Backdoored ‘secret’ chat app
Earth Berberoka uses a backdoored chat app called MiMi. Based on its website, which is written in Chinese, MiMi is a “secret” chat app — “mì mì (密密)” means “secret” — that is available for both Windows and macOS. MiMi contains an embedded malware that is downloaded and run in the background upon launch of the MiMi chat app executable on a victim’s machine. It should be noted that although the chat app contains malware, we did not analyze the app itself as it appeared to be a legitimately functioning chat app.

MiMi prompts new users to register with either a phone number or an email address. The choices of countries that the app supports are limited to the US, Canada, and a number of Asian countries, based on the phone number prefixes available in the registration drop-down menu. This supports our belief that gambling websites catering to Asian countries are the primary targets of Earth Berberoka’s campaign.

Our analysis uncovered that the macOS version of MiMi loads two malicious executables that are both samples of the oRAT malware, while the Windows version loads a recent 64-bit version of the PlugX malware. We discuss the technical details of both malware families in relation to their use by Earth Berberoka in a blog entry.

Fake cryptocurrency exchange app
Earth Berberoka also uses a fake BitGet app for macOS. BitGet is a Singapore-based cryptocurrency exchange platform.The preinstall script of the fraudulent BitGet app downloads and executes the oRAT malware.

Fake website delivering backdoored Adobe Flash Player installer
Earth Berberoka exploits a persistent cross-site scripting (XSS) vulnerability in a legitimate website to execute JavaScript code hosted in a third-party server. The injected code calls a PHP script named xss.php, verifies that the victim is running Windows, and sets a cookie to ensure that the code will not be executed more than once. A pop-up with a message in Chinese then appears, stating that the version of Adobe Flash Player is too old to display the content, and redirects the victim to a website offering a supposedly updated version of Adobe Flash Player.
Our investigation yielded multiple websites that promise victims a free updated version of Adobe Flash Player but in fact tricks them into downloading malware. Although Adobe has not supported Flash Player since Dec. 31, 2020, and all major websites have disabled Flash plug-ins, we learned that Adobe allows a third-party editor to deliver a version of Flash Player in mainland China through the flash.cn website.

Consistent with the other fake websites connected to this campaign, this malicious Flash website is also written in Chinese, suggesting that Earth Berberoka primarily targets Chinese-speaking individuals.

According to our telemetry, Earth Berberoka has abused two websites for its infection chain involving its backdoored Adobe Flash Player installer. One is a news website aimed at the Chinese community of a large US city, and the other is an unknown website that was offline and had no domain name at the time of our investigation.
Thwarting Earth Berberoka’s attacks
Our investigation of Earth Berberoka’s tools and infrastructure shows that this APT group has a lot of manpower and resources at its disposal. The group has used old yet upgraded malware along with malware families that it seems to have built specifically for this campaign. And as the online gambling market continues to grow, we can expect more attacks from Earth Berberoka and other APT groups that target this financially lucrative industry.
Our research paper “Operation Earth Berberoka: An Analysis of a Multivector and Multiplatform APT Campaign Targeting Online Gambling Sites” provides an in-depth technical analysis of Earth Berberoka’s tools, infrastructure, and potential attribution. This can help arm operators and users of gambling websites with the information that they need to avoid falling victim to Earth Berberoka’s attacks.